Data Backup for Small Business | 3-2-1 Checklist

Tom Reed
Read time: 9 minutes
Data Backup for Small Business | 3-2-1 Checklist

Data Backup for Small Business: IT Checklist (3-2-1)

Data backup for a small business means copying the systems and files you cannot afford to lose — email and SaaS data, file shares, servers, laptops, and phone/call recordings if you keep them — to places that survive a failed disk, ransomware, or a deleted tenant, then proving you can restore them. For roughly 20–100 person companies, a useful backup strategy is not “everything to one USB”; it follows the 3-2-1 rule (three copies, two media types, one offsite), automates nightly jobs, and schedules restore tests so the first restore is not during an outage. This playbook is a practical data-backup checklist for IT managers: what to cover, how to roll it out in 30 days, and how it sits next to business continuity and incident response — without fake RTO percentages or a hosted-PBX pitch.

What counts as a data backup (and how is it different from a business continuity plan)?

Data backup is making recoverable copies of the systems and files the business cannot afford to lose — mail and cloud drives, line-of-business SaaS, file servers and NAS, databases, endpoints with unique local files, and any softphone or call-recording stores you retain — then proving you can get them back.

A business continuity plan answers a different question: can people keep serving customers when a site, link, or key person is unavailable? Continuity is staffing, failover routes, and out-of-hours coverage. Backup is copies and restores. You need both; merging them into one vague “DR doc” usually leaves restore steps untested and continuity gaps unnamed.

Sync folders and recycle bins are not a full backup and recovery design. Version history helps with accidental deletes. It does not reliably survive ransomware that encrypts the live cloud, a compromised admin who empties retention, or a tenant wipe. Treat sync as convenience; treat backup as a separate, owned process with alerts and a restore runbook.

Why does a 20–100 person company need 3-2-1 instead of “we sync to one cloud drive”?

One cloud drive as the only copy fails the common failure modes SMBs actually hit:

  • Ransomware or a bad script that encrypts or deletes what staff can reach — including synced cloud files
  • A single admin laptop holding the “real” finance folder
  • USB-only backups that sit in the same office as the server
  • SaaS with recycle-bin retention but no third-party or immutable copy

The 3-2-1 backup rule (also written 3 2 1 backup rule) is the short design: keep three copies of important data, on two different media or system types, with at least one copy offsite or offline. In practice that often means production + on-site secondary (disk/NAS/appliance) + offsite or immutable object storage. Cloud backup for small business is one valid *destination type* under that offsite leg — not a consumer storage review and not a substitute for coverage of servers, SaaS, and endpoints.

Prefer automated backup over “remember Friday.” Document the schedule in a one-page backup policy: nightly SaaS and server jobs, weekly fulls where needed, who gets failure alerts, and how long you keep operational vs longer weekly/monthly sets. Separate backup-console credentials from day-to-day admin accounts and require MFA — pair with your MFA rollout and password manager so the backup console is not a shared sticky-note login.

External hard drive resting on a laptop keyboard — secondary media copy for a small-business 3-2-1 backup strategy

What should a small-business backup strategy cover (SaaS, servers, endpoints, and call data)?

Inventory by data class, not by vendor brochure:

  1. Microsoft 365 / Google Workspace — mail, drive, Teams/chat (or equivalents). Native recycle bins help mistakes; they are not a ransomware plan. Turn on or buy SaaS backup for critical mailboxes and drives.
  2. Line-of-business SaaS — CRM, finance, HR, ticketing. Confirm export/backup options and who owns them.
  3. File servers / NAS and on-prem apps — include databases; encrypt backups in transit and at rest.
  4. Endpoints — cover laptops that hold unique local files, or force work data into backed-up shares and align that rule with your acceptable use policy and MDM.
  5. Call recordings / softphone configs (if retained) — add them to the inventory so they are not the forgotten share. If company calling apps are in scope, say only approved softphones may place work calls and keep recordings on a path you actually back up; trials stay on sessiontalk.io.

Mark RPO targets in plain language your owners will recognise — for example “lose at most one business day of email” — without inventing industry averages. Pick what the business can tolerate, then design jobs and retention to match. Vendor-neutral backup software criteria beat fake “best backup software 2026” rankings: supported platforms, encryption, immutability/object-lock options, alerting, restore granularity, and admin MFA.

  • Artifact: Data backup / 3-2-1 — Job: Copy data so you can restore it — Not the same as: Business continuity (keep people/ops running out of hours)
  • Artifact: Restore test — Job: Prove a copy is usable — Not the same as: Incident response (contain and investigate an active incident)
  • Artifact: Backup policy — Job: Retention, scope, owners, alerts — Not the same as: Acceptable use policy (employee behaviour rules)
  • Artifact: Patch / MDM — Job: Keep systems current and enrolled — Not the same as: Making recoverable copies of data
  • Artifact: Offsite / immutable copy — Job: Survive site loss or ransomware encryption — Not the same as: A second folder on the same NAS

How do you prove backups work without staging a full disaster?

A backup you have never restored is a hope, not a control. You do not need a full site failover to prove backup and restore:

  1. Restore one mailbox or mail folder and time it.
  2. Restore one server file set or database sample to a safe target.
  3. Restore one SaaS item (file, site, or record export) through the backup console.
  4. Write what broke (permissions, missing encryption keys, wrong retention, silent job failure) and fix it.
  5. Wire job-failure alerts into helpdesk / on-call so a red job is a ticket, not a surprise on restore day.

Document the restore runbook next to incident response: backup failure or ransomware → contain (IR) → restore from a clean copy (this playbook) → resume ops (business continuity). Schedule quarterly restore tests and a semi-annual scope review when SaaS or servers change. Healthy systems still matter — keep patch management alongside recoverable copies so you are not only restoring what known bugs already broke.

IT professional working on a laptop beside server racks — checking backup jobs and restore readiness

What does a 30-day data backup checklist look like?

Week 1 — Inventory & scope

  1. List data classes: Microsoft 365 / Google Workspace (mail, drive, Teams/chat), line-of-business SaaS, file servers / NAS, databases, laptops, and any softphone / call-recording stores you retain.
  2. Mark RPO targets in plain language (e.g. “lose at most one business day of email”) — no fake industry averages; pick what the business can tolerate.
  3. Identify single points of failure: one admin laptop as the only copy, USB-only backups, SaaS with no third-party backup, shared passwords to the backup console (password manager).
  4. Name owners: who configures jobs, who gets failure alerts, who approves restore requests (helpdesk for the ticket path).

Week 2 — Design 3-2-1 & controls

  1. Apply 3-2-1: three copies of critical data, on two different media/types, with one copy offline or offsite (immutable / object-lock where your stack allows).
  2. Prefer automated backup over manual “remember Friday”; document the schedule (nightly SaaS + server; weekly full where needed).
  3. Separate backup credentials from day-to-day admin accounts; require MFA on the backup console (MFA).
  4. Decide retention: short operational window + longer weekly/monthly sets you can still afford — write it in a one-page backup policy.

Week 3 — Implement coverage

  1. Turn on or buy SaaS backup for mail/drive (native recycle bin is not a ransomware plan).
  2. Cover file servers / NAS and any on-prem apps; encrypt backups in transit and at rest.
  3. Cover endpoints that hold unique local files (or force work data into backed-up shares — align with AUP / MDM).
  4. If you retain call recordings or softphone configs, add them to the inventory — do not leave them as the forgotten share (approved calling apps only; softphone trials on sessiontalk.io).

Week 4 — Test, alert, review

  1. Run a restore test: one mailbox or folder, one server file set, one SaaS item — time it; fix gaps.
  2. Wire job-failure alerts to helpdesk / on-call (business continuity for who covers out-of-hours).
  3. Document the restore runbook next to IR: backup failure or ransomware → contain (incident response) → restore from clean copy (this post) → resume ops (BC).
  4. Schedule quarterly restore tests and a semi-annual scope review when SaaS or servers change.
  1. Purpose & scope (systems and data classes)
  2. RPO / retention targets (plain language)
  3. 3-2-1 design (on-site, secondary media, offsite)
  4. Automation & schedules
  5. Access control & MFA for backup consoles
  6. Restore request process (helpdesk ticket)
  7. Restore test cadence
  8. Escalation when jobs fail (IR / BC handoff)
  9. Review schedule

How do backup, business continuity, and incident response fit together?

Think of layers, not synonyms:

  • Data backup / 3-2-1 — copies you can restore; this post.
  • Restore test — proof the copies work before you need them.
  • Incident response — contain and investigate an active incident (ransomware, breach, wipe); restore is the recovery step after containment.
  • Business continuity — keep people and ops running while you restore or fail over.
  • Patch / MDM — reduce how often you need restores; they do not replace them.
  • AUP + password vault + MFA — where work data must live, and how backup consoles stay locked down.

Optional softphone note: if retained call recordings or approved calling apps are in your backup inventory, keep the CTA light and point trials at sessiontalk.io. Do not turn this playbook into a PBX product comparison.

Joiner and leaver data paths still matter: when someone leaves, decide what to retain vs wipe on the device onboarding/offboarding checklist, and for hybrid laptop data paths see the IT manager remote-work checklist.

FAQ

What is data backup for a small business?

Copying critical email, files, SaaS, servers, and endpoints to separate storage so you can restore after deletion, disk failure, or ransomware — and testing that restore.

Is OneDrive / Google Drive enough as a backup?

Sync and version history help with mistakes, but they are not a full 3-2-1 backup. Ransomware or a compromised admin can often hit the live cloud too — keep a separate/offsite copy for critical data.

What is the 3-2-1 backup rule?

Keep three copies of important data, on two different types of media or systems, with at least one copy offsite or offline.

How often should we test restores?

At least quarterly for a critical mailbox/folder and a server or SaaS sample — more often after major stack changes.

How does backup relate to business continuity?

Backup answers “can we get the data back?” Continuity answers “can the business keep operating while we do?” Link both; do not merge the posts.

Related Articles

More from the SessionTalk blog